4 ms·
I don’t see how the (to me) obvious fix would make IAM any harder. The bug is that they are treating account owner id as a string, allowing matching against it
by ComputerGuru 3y ago
I don’t see how the (to me) obvious fix would make IAM any harder. The bug is that they are treating account owner id as a string, allowing matching against it with prefix operations. It is a guid and should only have equal/not-equal tests.
As there are no “valid” IAM use cases for prefix matching on a resource id (you don’t control the resource id so you can never group resources by using a common prefix, etc) then there is no difficulty imposed by patching this.
The only question is backwards compatibility. If some idiot somewhere actually used a prefix match against a substring in production to match part of their actual resource id, this would presumably break it.
As for potential for harm, I don’t think it’s as low as you make it out to be. It’s hard to be anonymous online. This is another example of that. Forget common crawl or Carvana, and think dissident or whistleblower.
- zeroimpl 3y agoNote the ids appear to be 40-bit numbers, which isn’t great for security in the first place. I’m not sure off hand if there’s an efficient way to test all 2^40 values but seems feasible.